Splunk Phantom

Example of how to investigate and remediate phishing emails with Splunk Phantom?

Ultra Champion

Does anyone have examples of how to use Splunk Phantom to investigate and remediate phishing emails?

Labels (1)
0 Karma
1 Solution

Ultra Champion

The Splunk Product Best Practices team helped produce this response. Read more about example use cases in the Splunk Platform Use Cases manual.

For more information on this and other examples, download the free Splunk Security Essentials app on Splunkbase.


Undetected phishing emails can be devastating to an organization, and investigating them can be time consuming. Use the Splunk Phantom Phishing Investigate and Respond playbook to automate email investigations that analyze the email body, its attachments, and users who received the email so you can respond quickly to phishing attacks.

Load data

How to implement: To run the Splunk Phantom Phishing Investigate and Respond playbook, you need a Splunk Enterprise instance from which Phantom can draw data that ingests email server events.

Although there are several ways to get data into Phantom, this example uses the Phantom App for Splunk on Splunkbase. Verify that the playbook is configured to operate on splunk_events.

Before you run the playbook, verify that Splunk Phantom is receiving data from Splunk Enterprise. Also, verify your asset configurations on the Phantom Asset Configuration page, and that all assets are resolved on the Phantom Resolved Assets page.

Get insights

The Splunk Phantom Phishing Investigate and Respond playbook examines the artifacts from an ingested email and performs various reputation checks against the data. It triggers additional decisions if it needs further information, and can detonate an attachment in a sandbox if there is no information returned from a file reputation lookup. This playbook prompts you with the output from the reputation lookups so you can decide whether or not the email should be deleted.

To find the playbook, go to the Phantom main menu, select Playbooks, and search for phishing_investigate_and_respond.

Help

For more support, post a question to the Splunk Answers community.

View solution in original post

0 Karma

Ultra Champion

The Splunk Product Best Practices team helped produce this response. Read more about example use cases in the Splunk Platform Use Cases manual.

For more information on this and other examples, download the free Splunk Security Essentials app on Splunkbase.


Undetected phishing emails can be devastating to an organization, and investigating them can be time consuming. Use the Splunk Phantom Phishing Investigate and Respond playbook to automate email investigations that analyze the email body, its attachments, and users who received the email so you can respond quickly to phishing attacks.

Load data

How to implement: To run the Splunk Phantom Phishing Investigate and Respond playbook, you need a Splunk Enterprise instance from which Phantom can draw data that ingests email server events.

Although there are several ways to get data into Phantom, this example uses the Phantom App for Splunk on Splunkbase. Verify that the playbook is configured to operate on splunk_events.

Before you run the playbook, verify that Splunk Phantom is receiving data from Splunk Enterprise. Also, verify your asset configurations on the Phantom Asset Configuration page, and that all assets are resolved on the Phantom Resolved Assets page.

Get insights

The Splunk Phantom Phishing Investigate and Respond playbook examines the artifacts from an ingested email and performs various reputation checks against the data. It triggers additional decisions if it needs further information, and can detonate an attachment in a sandbox if there is no information returned from a file reputation lookup. This playbook prompts you with the output from the reputation lookups so you can decide whether or not the email should be deleted.

To find the playbook, go to the Phantom main menu, select Playbooks, and search for phishing_investigate_and_respond.

Help

For more support, post a question to the Splunk Answers community.

View solution in original post

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!